Deal of The Day! Hurry Up, Grab the Special Discount - Save 25% - Ends In 00:00:00 Coupon code: SAVE25
Welcome to Pass4Success

- Free Preparation Discussions

Exin Exam CITM Topic 5 Question 4 Discussion

Actual exam question for Exin's CITM exam
Question #: 4
Topic #: 5
[All CITM Questions]

What is the correct sequence of activities for a risk assessment?

Show Suggested Answer Hide Answer
Suggested Answer: C

The correct sequence for a risk assessment, as per ISO 31000 and ISO/IEC 27001, is: Establish context --- identify --- analyse --- evaluate --- treatment (C).

Establish context: Define the scope, objectives, and criteria for the risk assessment (e.g., organizational goals, assets, and risk appetite).

Identify: Identify potential risks (e.g., threats and vulnerabilities) that could impact objectives.

Analyse: Assess the likelihood and impact of identified risks to determine their severity.

Evaluate: Compare risks against risk criteria to prioritize them for treatment.

Treatment: Implement controls or strategies to mitigate, avoid, transfer, or accept risks.

Option A: Incorrect, as ''monitor and review'' is a post-treatment step, not the starting point.

Option B: Incorrect, as ''communication'' is not a distinct step in risk assessment; it's embedded throughout.

Option D: Incorrect, as it skips ''establish context,'' which is essential for defining the assessment's scope.

This sequence ensures a structured, systematic approach to risk assessment, aligning with organizational objectives.


Contribute your Thoughts:

Tresa
1 days ago
Option C looks good to me. Establishing the context first is crucial for a proper risk assessment.
upvoted 0 times
...

Save Cancel